Back to skill

Security audit

SwarmRecall Knowledge

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its knowledge-graph purpose, but it can send its API key and knowledge data to an environment-selected API server without clear validation.

Install only if you trust SwarmRecall with the knowledge you store. Keep SWARMRECALL_API_KEY private, do not use SWARMRECALL_API_URL unless it points to a trusted HTTPS endpoint you control, and avoid storing personal or sensitive information unless you explicitly want it persisted on the service.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:37
Finding

Unvalidated API Origin Override Can Disclose the Bearer Credential

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 37-43
Vulnerability Type: Untrusted API endpoint configuration with credential forwarding
Risk Level: Medium

Vulnerable Code Snippet:

text
## Authentication

All API requests require:

Authorization: Bearer <SWARMRECALL_API_KEY>

text

## API Base URL

`https://swarmrecall-api.onrender.com` (override with `SWARMRECALL_API_URL` if set)

Technical Analysis

The Skill requires every API request to include SWARMRECALL_API_KEY as a bearer credential while allowing the destination origin to be replaced through the SWARMRECALL_API_URL environment variable. It specifies no validation of the replacement URL's scheme, hostname, port, or trust status.

Consequently, an attacker who can influence the Agent's environment can set the override to an attacker-controlled endpoint. When the Skill subsequently follows its authentication instructions, it may transmit both the bearer credential and user-provided knowledge-graph content to that endpoint.

This is an insecure configuration pattern rather than evidence of intentional credential theft. The intended default API uses HTTPS and the documented service domain, but the unrestricted override weakens that protection.

Attack Path

  1. An attacker, compromised launcher, or unsafe deployment configuration sets SWARMRECALL_API_URL to an attacker-controlled URL, such as https://attacker.example.
  2. The Agent loads the Skill and accepts that environment variable as the API base URL.
  3. The Agent performs an entity, relation, search, traversal, or validation request.
  4. Following the authentication requirement, it attaches Authorization: Bearer &lt;SWARMRECALL_API_KEY&gt;.
  5. The attacker's server records the bearer credential and any submitted knowledge-graph data.
  6. The attacker may use the captured credential against the legitimate SwarmRecall API to access or modify data avail ...[truncated 636 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove SWARMRECALL_API_URL support if custom API origins are unnecessary.
  2. Otherwise, validate the resolved URL before attaching credentials:
    • Require the https scheme.
    • Permit only an explicit hostname allowlist.
    • Reject embedded credentials, unexpected ports, IP-literal hosts, redirects to other origins, and malformed URLs.
  3. Attach SWARMRECALL_API_KEY only when the final request origin exactly matches a trusted origin.
  4. Disable automatic cross-origin forwarding of the Authorization header during redirects.
  5. Require explicit user or administrator approval before enabling a non-default endpoint.
  6. Use separate, narrowly scoped credentials for development or self-hosted endpoints rather than reusing the production credential.
  7. Document that environment variables are security-sensitive configuration and must not be accepted from untrusted launchers or project-local environment files.
  8. If an untrusted override may already have been used, revoke and rotate the affected API key and review remotely stored knowledge for unauthorized access or modification.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

Delete an entity

text
DELETE /api/v1/knowledge/entities/:id

Create a relation

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

Delete a relation

text
DELETE /api/v1/knowledge/relations/:id

Traverse the graph

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
Knowledge entities and relations are affected by dream operations:

- **Duplicate entities**: Entity pairs of the same type with similar names/embeddings are identified. The agent reviews each pair and decides: merge, keep both, or archive one. For merges, migrate relations from the archived entity to the survivor before archiving.
- **Orphan cleanup**: Relations pointing to archived entities are automatically removed by Tier 1 dream operations (no agent action needed).
- **Knowledge graph enrichment**: During dreaming, the agent can read recent memories and extract new entities and relations, creating them via `POST /api/v1/knowledge/entities` and `POST /api/v1/knowledge/relations`.

Static analysis

No suspicious patterns detected.